North Korean-linked hackers stole an estimated $2.02 billion in cryptocurrency during 2025, while Amazon says it stopped more than 1,800 suspected North Korean operatives from joining the company since April 2024. These figures point to a broader campaign that uses cyber theft and fraudulent overseas IT work to generate money and access. They do not show that Amazon’s applicants carried out the crypto theft—or that every applicant was conclusively identified as North Korean.
What the headline figures mean
The two headline numbers describe different activity, reported by different sources. Chainalysis estimated that North Korean-linked hackers stole $2.02 billion in cryptocurrency during calendar year 2025, a record annual total and 51% more than the previous year. Amazon Chief Security Officer Stephen Schmidt said the company had stopped more than 1,800 suspected DPRK operatives from joining since April 2024. Neither number is a count of convictions or a complete measure of money ultimately available to North Korea.
| Figure | What it represents | Source and date |
|---|---|---|
| $2.02 billion | Estimated North Korean-linked cryptocurrency theft during calendar year 2025 | Chainalysis, December 18, 2025 |
| About $1.5 billion | Virtual assets stolen from Bybit in one incident, attributed by the FBI to North Korea’s TraderTraitor activity | FBI, February 21, 2025 |
| More than $3 billion | Treasury’s description of North Korea-affiliated cyber theft over the preceding three years | U.S. Treasury, November 4, 2025 |
| $6.75 billion | Chainalysis estimate of cumulative North Korean-linked cryptocurrency theft through the end of 2025 | Chainalysis, December 18, 2025 |
| More than 1,800 | Suspected DPRK operatives Amazon says it stopped from joining since April 2024—not confirmed hires removed from the company | Amazon CSO statement, reported in 2025 |
Chainalysis’s $2.02 billion is an estimate of assets stolen and attributed to North Korean-linked activity, not a government tally of recovered cash. The dollar valuation of cryptocurrency can change with market prices; a stolen asset’s stated value does not establish that it was converted to spendable currency or retained by the perpetrators. Some assets may be traced, frozen, recovered, or remain inaccessible. The estimate includes multiple attacks, not one operation. Chainalysis’s 2025 crypto-theft estimate explains its figures.
The FBI separately attributed the February 21, 2025 theft of approximately $1.5 billion in virtual assets from Bybit to North Korea’s TraderTraitor actors. That incident accounts for a large share of the annual estimate, but not all of it. The FBI’s Bybit alert describes its attribution and the movement of the stolen assets.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How crypto theft and fraudulent IT work fit together
These are related revenue and access streams, not one proven operation. Crypto theft involves attacks on digital-asset businesses, services, wallets, or their employees. IT-worker schemes use identity deception to obtain overseas employment or contracts, earn wages, and potentially gain access to company systems. A fraudulent hire could expose code, cloud environments, credentials, or financial systems; an outside hacking crew could pursue theft without any such hire. Public evidence does not establish that Amazon’s blocked applicants were responsible for the $2.02 billion estimate or the Bybit theft.
U.S. agencies say revenue from both cyber theft and IT-worker schemes benefits the DPRK government and supports its weapons programs. Treasury said in March 2026 that DPRK IT-worker schemes generated nearly $800 million during 2024. That is a government assessment of the schemes’ revenue and destination, not proof that every individual payment reached a particular weapons account. Treasury’s March 2026 announcement describes the sanctions action and its assessment.
How North Korean-linked crypto theft works
There is no single technique. U.S. and blockchain-analysis accounts describe a range of approaches, including targeted deception of employees and developers, credential theft, malware, and compromise of systems that control digital assets. Access to a private key, signing process, developer environment, or smart-contract code can expose assets without a conventional break-in at a company’s physical offices.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
After a theft, moving the assets quickly can complicate tracing and recovery. In the Bybit case, the FBI said the stolen assets were rapidly converted into Bitcoin and other virtual assets and dispersed across thousands of addresses and multiple blockchains. The Justice Department has described laundering methods in related cases that include chain hopping, token swaps, small transfers, fictitious identities, intermediary accounts, and commingling proceeds. These methods can make the trail harder to follow; they do not make transactions inherently untraceable. The Justice Department’s forfeiture complaint announcement outlines methods alleged in a case involving more than $7.74 million.
How IT-worker schemes operate
U.S. government advisories describe schemes in which workers seek remote jobs or contracts using fabricated, borrowed, or stolen identities. Some operate outside North Korea, including from countries such as China or Russia, and may rely on facilitators to supply identities, manage accounts, receive wages, or arrange equipment. A résumé can be fabricated, a real person’s identity stolen, or a genuine developer recruited into a network; “fake worker” does not describe every case equally.
One arrangement described by authorities is a U.S.-based laptop farm: a computer physically located in the United States is used to make an overseas worker’s connection appear domestic. A U.S. IP address therefore does not establish where the person is working. Once hired, a worker may have access to internal systems, repositories, cloud tools, or company communications. The FBI has warned of cases in which suspected workers stole proprietary data or source code and threatened to disclose it after being discovered. The FBI’s data-extortion alert describes that risk; Treasury’s July 2025 action discusses false identities and related facilitation.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The scheme can generate income even without a dramatic intrusion. Wages may be routed through third parties or transferred through networks supporting the DPRK government. A worker who gains access may also collect sensitive information, steal credentials, interfere with software, or enable later fraud. These are potential outcomes, not proof that every suspected worker carries out each one.
What Amazon’s 1,800 figure does—and does not—show
Amazon’s CSO said the company stopped more than 1,800 suspected DPRK operatives from joining since April 2024 and saw suspected DPRK-affiliated applications rise 27% quarter over quarter during 2025. The public wording is “suspected operatives.” It does not mean that 1,800 people were confirmed North Korean employees, hired and then removed, or found guilty of espionage.
Free tools Windows power users keep installed
One-click scans. No signup required.
Schmidt described a screening process combining an AI-powered model with human verification, background and credential checks, structured interviews, analysis of links to nearly 200 high-risk institutions, and review of application anomalies and geographic inconsistencies. The statement is an account of Amazon’s process, not a public audit of its accuracy or a guarantee that every fraudulent application will be detected. Schmidt’s statement is the primary source for the figures and method.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Amazon’s numbers matter as an indicator of sustained recruiting pressure at a major employer. They should not be treated as a proxy for the scale of crypto theft, nor as evidence that every remote or overseas applicant is suspicious. Government warnings about DPRK IT-worker schemes predate the latest figures; the FBI issued a data-extortion alert in January 2025, and enforcement actions continued through 2025 and 2026.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why technology and crypto companies are targets
Remote technical work can provide a route to foreign wages and system access without physical entry into a target country. Software engineers may encounter source repositories, deployment pipelines, cloud consoles, internal documentation, or financial systems as part of ordinary work. Roles in AI, machine learning, blockchain, and software engineering can be especially valuable because they combine technical access with high compensation. Crypto firms have the additional exposure of holding or moving digital assets in a fast-moving, globally distributed environment.
The risk is not limited to a direct transfer of funds. A compromised account may reveal proprietary code, employee information, or credentials that can be reused elsewhere. An employee or contractor with privileged access could create an opening for later theft, but employment fraud and cryptocurrency hacking remain distinct techniques.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How companies can reduce hiring and insider risk
No single screening tool can establish a candidate’s identity, location, competence, and intent. Companies should combine proportionate verification with access controls, human review, and clear escalation paths. Apply the same risk-based standards to all candidates; use anomalies to trigger review, not as automatic proof of wrongdoing.
Before making an offer
- Verify identity: Check identity documents through appropriate, lawful means and confirm that the person interviewed is the person who will perform the work. Repeat identity confirmation during onboarding and when issuing equipment or credentials.
- Verify work history and credentials independently: Contact prior employers through independently sourced channels and confirm education or certifications with the issuing institution when practical. Treat references that share contact details or deliver identical scripted responses as a reason to verify further, not as conclusive proof of fraud.
- Use structured, live interviews: Ask role-specific questions and use a practical exercise or live collaboration. Multiple interviewers and consistent criteria make it easier to assess whether the candidate can perform the work represented in the application.
- Review location inconsistencies carefully: Compare the declared work location with lawful, privacy-conscious signals such as device, network, time-zone, and travel information. A mismatch may warrant follow-up, but legitimate overseas work and ordinary technical causes can also produce anomalies.
At onboarding and during employment
- Issue managed devices and individual accounts: Require multifactor authentication, prohibit shared accounts for sensitive work, and keep identity tied to the person using the account. Reconfirm identity when issuing equipment or granting privileged access.
- Limit access by role: Start with least privilege. Separate development, production, financial, and signing environments; use just-in-time approval for sensitive actions and log administrative changes.
- Monitor for meaningful anomalies: Review unusual login locations, impossible travel, credential sharing, unexpected repository downloads, and abnormal data access. Monitoring should support investigation and be consistent with applicable privacy and employment rules.
- Plan rapid offboarding: Maintain a process to revoke credentials, sessions, tokens, and device access promptly when employment ends or an account is suspected to be compromised.
For procurement, finance, and compliance
- Check counterparties and payments: Verify the legal contracting entity and beneficial owners, apply sanctions screening required for the business, and investigate unexplained third-party payment recipients or informal payment arrangements.
- Coordinate across teams: HR and recruiting handle identity and work-history checks; IT and security manage devices and access; procurement validates vendors; finance reviews payment pathways; legal and compliance oversee sanctions, privacy, and employment-law obligations.
- For crypto businesses, secure the asset flow: Separate wallet custody and transaction approvals from general engineering access, monitor transactions, and establish escalation procedures for tracing or freezing assets where possible.
Location signals, résumé discrepancies, or AI risk scores can produce false positives. A legitimate remote worker may have unusual geography or documentation, and stolen identities can defeat checks that rely on one document or one contact channel. Automated screening should be paired with human review and a way to correct errors; it should not be the sole basis for rejecting a candidate.
Quick Recap
What the public record establishes
- Chainalysis estimated $2.02 billion in cryptocurrency theft attributed to North Korean-linked hackers during 2025; it is an estimate, not an exact government-confirmed total of recoverable proceeds.
- The FBI attributed the approximately $1.5 billion Bybit theft to North Korea’s TraderTraitor activity; this is one major incident within the larger annual estimate.
- Amazon’s CSO reported more than 1,800 suspected operatives stopped from joining since April 2024. That figure does not mean 1,800 proven North Korean employees or successful hires.
- The figures are evidence of parallel activity within a broader DPRK-linked cyber and revenue ecosystem, not proof that Amazon’s applicants caused the crypto theft.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




